CVE-2022-24913

MEDIUM

Java-merge-sort < 1.1.0 - Exposure to Wrong Actor

Title source: rule
STIX 2.1

Description

Versions of the package com.fasterxml.util:java-merge-sort before 1.1.0 are vulnerable to Insecure Temporary File in the StdTempFileProvider() function in StdTempFileProvider.java, which uses the permissive File.createTempFile() function, exposing temporary file contents.

Scores

CVSS v3 5.5
EPSS 0.0007
EPSS Percentile 20.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-377 CWE-668
Status published
Products (2)
com.fasterxml.util/java-merge-sort 0 - 1.1.0Maven
java-merge-sort_project/java-merge-sort < 1.1.0
Published Jan 12, 2023
Tracked Since Feb 18, 2026